Security should be integrated with enterprise risk, procurement, architecture, privacy, continuity, and audit. A control without an owner is not an operating control. Exceptions should be time-limited, justified, approved by appropriate authority, and tracked to closure.
Exercises
Turn a vague password policy into a testable standard.
Assign owners for five security controls.
Design an exception workflow.
Self-check
How does a standard differ from a policy?
Why assign control owners?
What makes an exception safe?
Self-Check Quiz
1. What does governance establish?
AnswerDirection, accountability, oversight, decision rights, and alignment between security and organizational objectives.
2. Should exceptions expire?
AnswerYes. Time limits and review prevent temporary risk acceptance from becoming permanent exposure.
Homework
Write a security-policy hierarchy for an enterprise.
Define control ownership and evidence.
Design an exception and escalation process.
Sample answerA policy states intent, a standard defines measurable requirements, and procedures explain operation. Owners produce evidence such as configuration, review, test, or log records. Exceptions document risk, compensating controls, approver, expiry, and reassessment trigger.